


Perceptive Security
SOC/SIEM Consultancy

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject mal…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 17:06:19
Source:
nvd.nist.gov
Web Technologies
TinyMCE, an open source rich text editor, contains a stored XSS vulnerability in its media plugin affecting versions prior to 5.11.1, 7.9.3, and 8.5.1. Attackers can inject malicious scripts through crafted data-mce-* attributes that execute when content is rendered. The vulnerability impacts all users with the media plugin enabled. Patches are available in versions 5.11.1, 7.9.3, and 8.5.1.
Technical details
Mitigation steps:
Affected products:
TinyMCE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47761
https://github.com/tinymce/tinymce/security/advisories/GHSA-vg35-5wq7-3x7w
https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/#overview
https://www.tiny.cloud/docs/tinymce/8/8.5.1-release-notes/#overview
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
